-
CVE-2026-89474
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:43:31
- Zuletzt bearbeitet 14.09.2026 13:19:03
- Erkennungen
power: supply: bq256xx: drain usb_work before freeing the charger
In the Linux kernel, the following vulnerability has been resolved: power: supply: bq256xx: drain usb_work before freeing the charger The USB-PHY notifier queues usb_work, whose handler calls power_supply_changed(bq->charger). The reset devm action only unregisters the notifier and was registered before the power supplies, so devm frees bq->charger on unwind before the action runs; a usb_work still queued can then dereference it. Register the reset action after the power supplies, so it unregisters the notifiers and drains usb_work before the supplies are released. Initialize usb_work and obtain the PHY references before registering the notifiers, so the worker cannot run before the supplies exist. Found by static analysis.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
32e4978bb920d047fe5de3ea42d176f267c01f63
Version <
9dcfdf6c598301b278f0b3490eb2bf4f600524e2
Status
affected
Version
32e4978bb920d047fe5de3ea42d176f267c01f63
Version <
fd08d4dbbec07a44f01b0ddb041912be0dc88f8c
Status
affected
Version
32e4978bb920d047fe5de3ea42d176f267c01f63
Version <
2cfb59dc9df8b5ebdd95e3d874a7f4690cee2bc8
Status
affected
Version
32e4978bb920d047fe5de3ea42d176f267c01f63
Version <
9a467bd1e6811011026ad4c8de701b940d88a00c
Status
affected
Version
32e4978bb920d047fe5de3ea42d176f267c01f63
Version <
9e1aba34df9a87d53460888e05718717c0f69343
Status
affected
Version
32e4978bb920d047fe5de3ea42d176f267c01f63
Version <
c8addb842ae8dcf69c15fc976e33e3bd538a41d7
Status
affected
Version
32e4978bb920d047fe5de3ea42d176f267c01f63
Version <
2dd6cd823777bea6d9a880a12a92a73ec76aee0b
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.12
Status
affected
Version
0
Version <
5.12
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/9a467bd1e6811011026ad4c8de701b940d88a00c
https://git.kernel.org/stable/c/9e1aba34df9a87d53460888e05718717c0f69343
https://git.kernel.org/stable/c/c8addb842ae8dcf69c15fc976e33e3bd538a41d7
https://git.kernel.org/stable/c/2dd6cd823777bea6d9a880a12a92a73ec76aee0b
https://git.kernel.org/stable/c/2cfb59dc9df8b5ebdd95e3d874a7f4690cee2bc8
https://git.kernel.org/stable/c/9dcfdf6c598301b278f0b3490eb2bf4f600524e2
https://git.kernel.org/stable/c/fd08d4dbbec07a44f01b0ddb041912be0dc88f8c